The AI Act applies where the output is used in the Union. Your servers being in Dubai does not help.
Article 2 covers providers and deployers established in a third country where the output produced by the AI system is used in the Union. Prohibitions and AI literacy have applied since 2 February 2025, and the general application date is 2 August 2026.

- 2 Feb 2025Prohibitions and AI literacy already apply
- 2 Aug 2026The general application date
- 8 prohibitionsListed in Article 5(1)
- Third countryExplicitly in scope under Article 2
Ask where the output is used, not where the company is registered.
Article 2 was drafted specifically to prevent the obvious avoidance, and it is the reason UAE companies with no EU entity are still in scope.
- The provision at Article 2(1)(c) covers providers and deployers that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union. Location of the company, the servers and the model are not the test.
- A UAE company that screens CVs for a client with EU operations, generates content published to EU audiences, or scores applications used by an EU business is producing output used in the Union, whatever the contract says about governing law.
- Article 2(1)(a) separately covers providers placing AI systems on the market or putting them into service in the Union, and placing general-purpose AI models on the Union market, irrespective of whether established in the Union or in a third country.
- The practical exercise is short. List your AI systems, and for each one ask where the output ends up. Any answer involving the Union puts that system inside a scope question worth taking seriously rather than assuming away.
Eight things a UAE organisation needs to establish.
Third country establishment is explicitly covered
Article 2 applies to providers placing AI systems on the market in the Union irrespective of whether they are established in the Union or in a third country, and to providers and deployers located in a third country where the output produced by the AI system is used in the Union.
It arrives in stages, and two have passed
Prohibitions and AI literacy have applied since 2 February 2025. General-purpose AI and governance provisions since 2 August 2025. The general application date is 2 August 2026, and the Article 6(1) high-risk classification rules apply from 2 August 2027.
Eight practices are prohibited outright
Manipulative or subliminal techniques, exploitation of vulnerabilities by age, disability or social or economic situation, social scoring, predicting criminal offences solely from profiling or personality traits, untargeted facial image scraping, workplace and education emotion inference, sensitive biometric categorisation, and real-time remote biometric identification for law enforcement.
AI literacy is an obligation, not a suggestion
Providers and deployers must take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and other persons dealing with the operation and use of AI systems on their behalf. It has applied since February 2025 and is frequently missed.
People must be told they are talking to an AI
Providers must ensure AI systems intended to interact directly with natural persons are designed so those persons are informed they are interacting with an AI system, unless this is obvious. That covers chat interfaces, voice agents and support automation.
Synthetic output must be machine-readable marked
Providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. That is a product engineering requirement rather than a policy statement.
Deep fakes and public interest text need disclosure
Deployers generating or manipulating image, audio or video constituting a deep fake must disclose that the content has been artificially generated. The same applies to text published to inform the public on matters of public interest.
Emotion and biometric systems require notice
Deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of the operation of the system, in a clear and distinguishable manner at the latest at the time of first interaction or exposure.
What applies from when.
| Provisions | Applies from | |
|---|---|---|
| Chapters I and II, prohibitions and AI literacy | 2 February 2025 | |
| General-purpose AI, governance, Chapter III Section 4 | 2 August 2025, excluding Article 101 penalties | |
| The Regulation generally | 2 August 2026 | |
| Article 6(1) high-risk classification | 2 August 2027 | |
| Entry into force | Twentieth day after Official Journal publication | |
| Prohibited practices under Article 5 | Already in force since February 2025 | |
| Article 4 AI literacy duty | Already in force since February 2025 | |
| Article 50 transparency duties | With the general application date |
Four things that keep an AI Act response grounded.
We screen for prohibitions first
Because they have applied since 2 February 2025 and there is no compliance path for them. A system that infers emotions in a workplace or scrapes facial images without targeting is not a documentation problem, and finding that out early matters more than anything else.
We apply the scope test as written
Providers and deployers in a third country are covered where the output produced by the AI system is used in the Union. We test each system against that wording rather than against where the company or the infrastructure happens to be located.
We treat AI literacy as the quick win it is
Article 4 requires measures to ensure a sufficient level of AI literacy among staff operating AI systems, taking account of their knowledge, the context of use and the people affected. It is already in force, it is achievable quickly, and it is commonly missed entirely.
We separate the Act from voluntary frameworks
A governance framework helps you meet the Act and does not discharge it. Conversely the Act does not give you a governance framework. Knowing which of the two a customer, board or regulator is actually asking about prevents a lot of wasted effort.
Four phases across roughly eight to fourteen weeks.
- 01Weeks 1 to 2
Scope and prohibition screening
Every AI system listed, with where its output is used. Then each screened against the eight prohibited practices in Article 5, which have applied since 2 February 2025 and admit no compliance route. That screening is the immediate priority.
- AI system inventory with output destinations
- In scope determination per system under Article 2
- Article 5 prohibition screening completed
- Any prohibited practice escalated immediately
- 02Weeks 3 to 5
Role and AI literacy
Whether you are a provider, a deployer, an importer or a distributor for each system, since the obligations differ. Then the Article 4 duty to ensure, to your best extent, a sufficient level of AI literacy among staff operating those systems.
- Role determined per system
- AI literacy programme scoped by role and context
- Training delivered and completion recorded
- Authorised representative question addressed where relevant
- 03Weeks 6 to 10
Transparency obligations
Disclosure that a person is interacting with an AI system, machine-readable marking of synthetic output, deep fake disclosure and public interest text disclosure, and notice for emotion recognition or biometric categorisation systems.
- Interaction disclosure implemented where not obvious
- Machine-readable marking of synthetic output specified
- Deep fake and public interest text disclosure in place
- Accessibility of the disclosures verified
- 04Weeks 11 to 14
High-risk assessment and governance
Whether any system falls into the high-risk classification, whose rules under Article 6(1) apply from 2 August 2027, and the governance that keeps the position current as systems and their uses change over time.
- High-risk exposure assessed per system
- Documentation approach agreed where applicable
- Change control so new uses are re-screened
- Board and customer reporting position established
Six situations that put a UAE business in scope.
A Dubai company screening candidates for EU employers
The system runs in the UAE and the output, a ranking or a shortlist, is used by an employer in the Union. That is output produced by the AI system used in the Union, which is the Article 2(1)(c) test in its plainest form.
A software vendor with a chat assistant in the product
Where the product is used by customers in the Union, providers must ensure people are informed they are interacting with an AI system unless it is obvious. That is an interface requirement, and it is far cheaper to build than to retrofit.
An agency generating content for European audiences
Synthetic audio, image, video or text must be marked in a machine-readable format and detectable as artificially generated. Deep fakes require disclosure, as does text published to inform the public on matters of public interest.
An organisation using emotion analytics on staff
Inferring emotions of a natural person in the areas of workplace and education institutions is a prohibited practice, subject to a medical or safety exception. Where any part of that touches the Union, this is not a risk to manage but a practice to stop.
A firm scoring customers or applicants
Social scoring based on social behaviour or inferred personal characteristics leading to detrimental treatment is prohibited, and predicting criminal offences solely from profiling or personality traits is prohibited. Scoring systems need careful reading against both.
A group with an EU parent asking questions
Group compliance functions have been asking since early 2025, because prohibitions and AI literacy applied from 2 February 2025. A UAE entity that cannot describe its AI systems is a gap in the group answer rather than a local matter.
How UAE organisations are treating the AI Act.
| Feature | Screened and evidenced | Waiting for August 2026 | Assumed out of scope |
|---|---|---|---|
Prohibited practice screening done | Yes | Not yet | No |
Prohibitions already in force | Understood | Overlooked | Overlooked |
AI literacy obligation met | Delivered and recorded | Planned | Unknown |
Scope test applied correctly | Output based | Partially | Establishment based |
Interaction disclosure implemented | Yes | Designed | No |
Synthetic output marking | Specified | Considered | Not considered |
Answer for an EU customer | Documented | In progress | None |
Exposure if a prohibition applies | Identified early | Discovered late | Discovered by somebody else |
Effort to reach position | Weeks | Deferred | None |
Suitable for a company with EU output | Yes | Risky | No |
Eight questions that must all be answered no.
Manipulation and vulnerability
- Does it use subliminal or deceptive techniques?Article 5(1)(a).
- Does it exploit age, disability or hardship?Article 5(1)(b).
- Does it score people socially?Article 5(1)(c).
Profiling and biometrics
- Does it predict criminality from profiling alone?Article 5(1)(d).
- Does it scrape facial images untargeted?Article 5(1)(e).
- Does it infer emotions at work or in education?Article 5(1)(f).
Sensitive inference
- Does it infer race, beliefs or sexual orientation?Article 5(1)(g).
- Real-time biometric identification in public?Article 5(1)(h).
Five steps, in the order that risk actually arrives.
- 1
Inventory AI systems and where their output goes
The scope test at Article 2(1)(c) turns on whether the output produced by the AI system is used in the Union. That means the inventory needs a destination column, and it needs to include systems embedded in products as well as ones built in house.
- 2
Screen every system against Article 5
The eight prohibited practices, which have applied since 2 February 2025. There is no compliance route for these, so identifying one is an immediate escalation rather than an item on a remediation plan with a date attached to it.
- 3
Establish your role for each system
Provider, deployer, importer or distributor, since obligations differ by role and a single organisation is frequently more than one across its portfolio. Authorised representative requirements are considered here where they arise.
- 4
Deliver the AI literacy obligation
Measures to ensure, to your best extent, a sufficient level of AI literacy among staff and others operating AI systems on your behalf, taking into account their knowledge, experience, training, the context of use, and the people the systems are used on.
- 5
Build the transparency and high-risk position
Interaction disclosure, machine-readable marking of synthetic output, deep fake and public interest text disclosure, and notice for emotion recognition and biometric categorisation. Then the high-risk assessment ahead of the August 2027 classification date.
What UAE organisations ask about the EU AI Act.
The staged timeline means part of this is a present obligation, not a 2026 project.
Organisations reading about the general application date frequently conclude they have time, and for two significant chapters they do not.
- Chapters I and II applied from 2 February 2025. That covers the prohibited practices and the AI literacy obligation, both of which are in force now. An organisation operating a prohibited practice is not approaching a deadline, it is past one.
- General-purpose AI and governance provisions applied from 2 August 2025, excluding the Article 101 penalties. Organisations building on or providing general-purpose models have been inside that scope for some time already.
- The general application date of 2 August 2026 covers the bulk of the Regulation, including the transparency duties in Article 50. That is the date most planning is built around, and it is the third milestone rather than the first.
- The Article 6(1) high-risk classification rules apply from 2 August 2027. That later date is why high-risk assessment can be planned rather than rushed, provided the prohibition screening and the literacy obligation have already been addressed.
List every AI system you operate, and write down where its output is used.
Any answer involving the Union puts that system inside a scope question. Then screen those systems against the eight prohibited practices, which have applied since February 2025.
Related Services
Explore more solutions that work great with this service
AI governance framework
Know what AI is in use, and who approved it.
GDPR for UAE Businesses
When EU law actually reaches a UAE business, and when it does not
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
Privacy Impact Assessment
DPIA done at design stage, necessity tested properly
IT Risk Assessment
A short register with an owner against every risk
Compliance as a Service
Keeping the position true between assessments
Virtual CISO Dubai
Security governance and accountability, not more tools
Security Policy Development
Policies you can actually comply with